CVE-2024-28741

HIGH

NorthStar C2 XSS to Agent RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-28741. PoCs published by chebuya, h00die, chebuya, including Metasploit module exploits/windows/http/northstar_c2_xss_to_agent_rce.

AI-analyzed exploit summary This PoC exploits CVE-2024-28741, a stored XSS vulnerability in NorthStar C2, by sending multiple malicious agent registration requests to build a JavaScript payload in the logs web page, enabling remote command execution on NorthStar C2 agents.

Description

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

Exploits (2)

nomisec WORKING POC 5 stars
by chebuya · poc
https://github.com/chebuya/CVE-2024-28741-northstar-agent-rce-poc

This PoC exploits CVE-2024-28741, a stored XSS vulnerability in NorthStar C2, by sending multiple malicious agent registration requests to build a JavaScript payload in the logs web page, enabling remote command execution on NorthStar C2 agents.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NorthStar C2 v1.0
No auth needed
Prerequisites: Access to the target NorthStar C2 teamserver · Network connectivity to the callback server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by h00die, chebuya · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/northstar_c2_xss_to_agent_rce.rb

This Metasploit module exploits a stored XSS vulnerability in NorthStar C2 (CVE-2024-28741) to achieve unauthenticated session hijacking and subsequent remote code execution on compromised agents. The exploit chains XSS with agent command execution to run arbitrary payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NorthStar C2 (prior to commit 7674a44)
No auth needed
Prerequisites: Network access to NorthStar C2 web interface · At least one active agent connected to the C2
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.7816
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Published Apr 06, 2024
Tracked Since Feb 18, 2026